CVE-2026-1965 describes a logical error in libcurl (haxx curl) where it can incorrectly reuse Negotiate-authenticated HTTP/HTTPS connections, potentially sending requests with new credentials over a connection authenticated by different, older credentials. Rated as Medium (CVSS 6.5), this vulnerability has a network attack vector and low attack complexity, allowing an attacker with low privileges to achieve high integrity impact by performing unauthorized actions. There is no evidence of active exploitation, nor are public exploit codes available (Metasploit, Nuclei, ExploitDB are all None). Despite this, the vulnerability has garnered community attention with 14 mentions and several vendor advisories. Applications can mitigate this issue by disabling libcurl's connection reuse.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.10.6, <= 7.10.6CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.10.7, <= 7.10.7CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.10.8, <= 7.10.8CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.11.0, <= 7.11.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.11.1, <= 7.11.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.